Skip to content

Releases: github/dependabot-action

v3.0.0

18 May 16:22
032bfdf

Choose a tag to compare

What's Changed

Full Changelog: v2.33.0...v3.0.0

v2.33.0

15 May 19:43
0facf34

Choose a tag to compare

What's Changed

Full Changelog: v2...v2.33.0

v2.32.0

15 May 01:34
0fd4908

Choose a tag to compare

What's Changed

  • Fix string comparison in bump-version script by @jeffwidman in #1638
  • Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1643
  • Bump the prod-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1647
  • Bump the dev-dependencies group with 3 updates by @dependabot[bot] in #1648
  • Bump handlebars from 4.7.8 to 4.7.9 by @dependabot[bot] in #1644
  • Bump lodash from 4.17.21 to 4.18.1 by @dependabot[bot] in #1650
  • Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1653
  • Bump dependabot/proxy from v2.0.20260404001356 to v2.0.20260406203606 in /docker in the dependabot-core-images group by @dependabot[bot] in #1654
  • Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1655
  • Bump dependabot/fetch-metadata from 2.5.0 to 3.0.0 by @dependabot[bot] in #1646
  • Bump the dev-dependencies group across 1 directory with 4 updates by @dependabot[bot] in #1651
  • Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1656
  • Set NODE_OPTIONS to increase V8 heap for large monorepos by @davidwinder-gyde in #1649
  • Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1657
  • Bump actions/create-github-app-token from 3.0.0 to 3.1.1 by @dependabot[bot] in #1658
  • Bump the dependabot-core-images group in /docker with 29 updates by @dependabot[bot] in #1664
  • Update proxy image by @robaiken in #1665
  • Add missing ecosystems to automatic GitHub Packages auth by @JamieMagee in #1668
  • Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1669
  • Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1676
  • Add updater container support for conda, deno, and nix by @Copilot in #1681
  • Bump the dependabot-core-images group across 1 directory with 29 updates by @dependabot[bot] in #1679
  • Bump protobufjs from 7.4.0 to 7.5.6 by @dependabot[bot] in #1680
  • Bump the dev-dependencies group across 1 directory with 8 updates by @dependabot[bot] in #1682
  • Bump the dependabot-core-images group in /docker with 32 updates by @dependabot[bot] in #1687
  • Bump tar-stream from 3.1.8 to 3.2.0 in the prod-dependencies group across 1 directory by @dependabot[bot] in #1678
  • Bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 by @dependabot[bot] in #1670
  • Bump dockerode from 4.0.10 to 5.0.0 by @dependabot[bot] in #1673
  • v2.32.0 by @Nishnha in #1690

New Contributors

Full Changelog: v2...v2.32.0

v2.31.0

18 Mar 22:07
5fcf281

Choose a tag to compare

What's Changed

  • Update image pull backoff params by @pavera in #1592
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251124194534 to v2.0.20251219172147 in /docker by @dependabot[bot] in #1596
  • Bump the dependabot-core-images group in /docker with 28 updates by @dependabot[bot] in #1595
  • Bump the dev-dependencies group across 1 directory with 8 updates by @dependabot[bot] in #1602
  • Bump the prod-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1598
  • Bump actions/create-github-app-token from 2.2.0 to 2.2.1 by @dependabot[bot] in #1587
  • Bump dependabot/fetch-metadata from 2.4.0 to 2.5.0 by @dependabot[bot] in #1597
  • Bump eslint-plugin-github from 5.1.8 to 6.0.0 by @dependabot[bot] in #1438
  • Bump the dev-dependencies group with 3 updates by @dependabot[bot] in #1604
  • Bump @actions/core from 1.11.1 to 2.0.2 by @dependabot[bot] in #1605
  • Bump globals from 16.5.0 to 17.1.0 by @dependabot[bot] in #1609
  • Bump @types/dockerode from 3.3.47 to 4.0.1 by @dependabot[bot] in #1606
  • elevate GITHUB_TOKEN to packages feed credential by @brettfo in #1603
  • Update reference to Dependabot proxy by @JamieMagee in #1610
  • Add precommit ghcr version and sha by @AbhishekBhaskar in #1621
  • Pass through OPENSSL_FORCE_FIPS_MODE env var to containers by @jeffwidman in #1622
  • Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1623
  • Add devcontainer config to pin Node version from .nvmrc by @Copilot in #1626
  • Bump actions/create-github-app-token from 2.2.1 to 3.0.0 by @dependabot[bot] in #1632
  • Bump minimatch from 3.1.2 to 3.1.5 by @dependabot[bot] in #1627
  • Bump the dev-dependencies group across 1 directory with 8 updates by @dependabot[bot] in #1633
  • Bump tar-stream from 3.1.7 to 3.1.8 in the prod-dependencies group across 1 directory by @dependabot[bot] in #1634
  • Bump @types/node from 24.10.1 to 25.2.0 by @dependabot[bot] in #1617
  • Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1630
  • Bump the dependabot-core-images group in /docker with 29 updates by @dependabot[bot] in #1637
  • v2.31.0 by @jeffwidman in #1639

New Contributors

Full Changelog: v2...v2.31.0

v2.30.0

05 Dec 17:52
e2b700a

Choose a tag to compare

What's Changed

  • remove unused output and repo path code by @jakecoffman in #1537
  • Bump the dependabot-core-images group in /docker with 25 updates by @dependabot[bot] in #1516
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250804193157 to v2.0.20250826205840 in /docker by @dependabot[bot] in #1534
  • add invocation of specific commands (graph) by @jakecoffman in #1540
  • Pass OIDC environment variables to proxy by @JamieMagee in #1544
  • Bump actions/create-github-app-token from 2.1.1 to 2.1.4 by @dependabot[bot] in #1538
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250826205840 to v2.0.20251003180402 in /docker by @dependabot[bot] in #1546
  • Bump actions/setup-node from 4 to 5 by @dependabot[bot] in #1536
  • Bump github/codeql-action from 3 to 4 by @dependabot[bot] in #1548
  • Delete the custom CodeQL config in favor of default config by @jeffwidman in #1552
  • add tenant-id and client-id to credentials by @brettfo in #1553
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251010195543 to v2.0.20251014173146 in /docker by @dependabot[bot] in #1554
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251014173146 to v2.0.20251015175503 in /docker by @dependabot[bot] in #1555
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251015175503 to v2.0.20251023141128 in /docker by @dependabot[bot] in #1557
  • Adding Julia to actions by @robaiken in #1558
  • Adding Bazel to actions by @robaiken in #1560
  • Extract the updater image's SHA from the input parameters and pass it as an envvar by @brrygrdn in #1561
  • Bump actions/setup-node from 5 to 6 by @dependabot[bot] in #1556
  • Bump on-headers, compression and morgan by @dependabot[bot] in #1565
  • Bump the prod-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1539
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251023141128 to v2.0.20251107162748 in /docker by @dependabot[bot] in #1563
  • Adding OpenTofu image by @robaiken in #1566
  • Bump the dev-dependencies group across 1 directory with 16 updates by @dependabot[bot] in #1570
  • Bump eslint-plugin-jest from 28.11.0 to 29.2.1 by @dependabot[bot] in #1579
  • Bump actions/create-github-app-token from 2.1.4 to 2.2.0 by @dependabot[bot] in #1574
  • Bump actions/checkout from 5 to 6 by @dependabot[bot] in #1573
  • Bump jest-circus from 29.7.0 to 30.2.0 by @dependabot[bot] in #1577
  • Bump @types/node from 22.15.21 to 24.10.1 by @dependabot[bot] in #1578
  • Bump the dev-dependencies group with 4 updates by @dependabot[bot] in #1575
  • Set check-dist workflow permissions by @Nishnha in #1581
  • Set test workflow permissions by @Nishnha in #1582
  • Bump the dev-dependencies group with 2 updates by @dependabot[bot] in #1584
  • Bump node-forge from 1.3.1 to 1.3.2 by @dependabot[bot] in #1583
  • Bump jest and @types/jest by @dependabot[bot] in #1576
  • Bump @actions/http-client from 2.2.3 to 3.0.0 by @dependabot[bot] in #1569
  • Update README.md to add deploy instructions by @honeyankit in #1429
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251113195050 to v2.0.20251124194534 in /docker by @dependabot[bot] in #1580
  • Bump the dependabot-core-images group in /docker with 28 updates by @dependabot[bot] in #1572

New Contributors

Full Changelog: v2.29.0...v2.30.0

v2.29.0

05 Sep 09:03
6b07cf6

Choose a tag to compare

What's Changed

  • credential type is not a secret by @jakecoffman in #1517
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250618164131 to v2.0.20250701191801 in /docker by @dependabot[bot] in #1511
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250715192211 to v2.0.20250716173616 in /docker by @dependabot[bot] in #1518
  • handle NPM metadata missing registry key by @jakecoffman in #1519
  • extract registry from url for other ecosystems by @jakecoffman in #1520
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250716173616 to v2.0.20250717140017 in /docker by @dependabot[bot] in #1521
  • remove automerge by @jakecoffman in #1515
  • set index-url from url by @jakecoffman in #1522
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250717140017 to v2.0.20250724172018 in /docker by @dependabot[bot] in #1525
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250724172018 to v2.0.20250731100605 in /docker by @dependabot[bot] in #1527
  • Add path to npm registry definition by @pavera in #1531
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250731100605 to v2.0.20250804193157 in /docker by @dependabot[bot] in #1529
  • Bump actions/create-github-app-token from 2.0.6 to 2.1.1 by @dependabot[bot] in #1533
  • Bump actions/checkout from 4 to 5 by @dependabot[bot] in #1532
  • Updating updater images to the version 20250904090707 by @thavaahariharangit in #1535

Full Changelog: v2...v2.29.0

v2.28.0

08 Jul 16:53
8a8ecd4

Choose a tag to compare

What's Changed

Full Changelog: v2...v2.28.0

v2.27.0

09 Jun 20:14
4bf3d89

Choose a tag to compare

What's Changed

  • Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1453
  • Bump tar-fs from 2.1.2 to 2.1.3 in the npm_and_yarn group by @dependabot in #1489

Full Changelog: v2.26.0...v2.27.0

v2.26.0

06 Jun 10:29
64997d7

Choose a tag to compare

What's Changed

  • Bump eslint-import-resolver-typescript from 3.8.3 to 4.2.2 by @dependabot in #1439
  • Remove unnecessary hardcoding of ref by @jeffwidman in #1456
  • Enable caching of npm install/npm ci for setup-node action by @jeffwidman in #1457
  • fix detached head state on push by @jakecoffman in #1464
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250404141843 to v2.0.20250425201519 in /docker by @dependabot in #1465
  • Bump dockerode from 4.0.5 to 4.0.6 in the prod-dependencies group by @dependabot in #1460
  • Bump @actions/github from 6.0.0 to 6.0.1 in the prod-dependencies group by @dependabot in #1471
  • Bump dependabot/fetch-metadata from 2.3.0 to 2.4.0 by @dependabot in #1470
  • Bump the dev-dependencies group across 1 directory with 14 updates by @dependabot in #1468
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250501191828 to v2.0.20250510074035 in /docker by @dependabot in #1472
  • Update certificate to support python 3.13 by @thavaahariharangit in #1475
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250510074035 to v2.0.20250515192846 in /docker by @dependabot in #1477
  • Switch from PAT to federated secret for pulling ghcr images by @jeffwidman in #1478
  • Bump commander from 13.1.0 to 14.0.0 by @dependabot in #1480
  • Bump lint-staged from 15.5.2 to 16.0.0 by @dependabot in #1473
  • Switch to using an App token instead of a PAT by @jeffwidman in #1442
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250515192846 to v2.0.20250521082831 in /docker by @dependabot in #1482
  • add a manually run build workflow by @jakecoffman in #1486
  • Bump the dev-dependencies group across 1 directory with 9 updates by @dependabot in #1485
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250521082831 to v2.0.20250522155011 in /docker by @dependabot in #1483
  • Bump undici from 5.28.5 to 5.29.0 in the npm_and_yarn group by @dependabot in #1476
  • Bump actions/create-github-app-token from 1.11.6 to 2.0.6 by @dependabot in #1484
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250522155011 to v2.0.20250602172812 in /docker by @dependabot in #1490
  • v2.26.0 by @thavaahariharangit in #1491

Full Changelog: v2...v2.26.0

v2.25.0

11 Apr 15:27
9d166f4

Choose a tag to compare

What's Changed

  • Implement feature to capture metrics inside Dependabot Actions to post to Dependabot API by @honeyankit in #1428
  • Adding helm ecosystem image by @robaiken in #1430
  • Bump commander from 12.1.0 to 13.1.0 by @dependabot in #1398
  • Bump the dev-dependencies group across 1 directory with 5 updates by @dependabot in #1434
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250310190033 to v2.0.20250320211425 in /docker by @dependabot in #1433
  • Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1432
  • Bump eslint from 8.57.0 to 9.22.0 by @dependabot in #1424
  • Make typescript compile to "es2022" by @jeffwidman in #1435
  • Remove deprecated command invocation by @jeffwidman in #1436
  • Remove unused fetch-metadata step by @jeffwidman in #1441
  • Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250320211425 to v2.0.20250404141843 in /docker by @dependabot in #1448
  • Bump dockerode from 4.0.4 to 4.0.5 in the prod-dependencies group by @dependabot in #1445
  • Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1451
  • Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1452
  • v2.25.0 by @jakecoffman in #1454

Full Changelog: v2...v2.25.0